گروه توسعه همراه تل
گروه توسعه همراه تل

Security Engineer

Tehran/Jordan
Full Time
Sat To Wed
-
Loan -Health insurance -Parking space

این فرصت شغلی چقدر برای من مناسب است؟

501 - 1000 employees
Internet Provider / E-commerce / Online Services
Iranian company dealing only with Iranian entities
1394
Privately held
توضیحات بیشتر

key Requirements

4 years experience in similar position

Job Description

We are looking for a hands-on Security Engineer focused on penetration testing, application security, and DevSecOps. You will work closely with Software Engineering and DevOps teams to identify security risks and integrate security throughout the software development lifecycle.
What You'll Do
  • Perform penetration testing and security assessments on web applications, APIs, mobile applications, and internal services.
  • Identify, validate, document, and prioritize vulnerabilities and provide practical remediation guidance.
  • Perform manual security testing beyond automated vulnerability scanning.
  • Conduct secure code reviews, threat modeling, and security design reviews.
  • Review authentication and authorization mechanisms such as OAuth 2.0, OIDC, JWT, SSO, MFA, IAM, and RBAC.
  • Work with engineering teams to reproduce and remediate security issues.
  • Integrate security controls into CI/CD pipelines, including SAST, DAST, SCA, secrets detection, container scanning, and IaC scanning.
  • Define risk-based security gates for builds and releases.
  • Automate repetitive security testing and vulnerability management activities.
  • Support secure usage of Docker and Kubernetes.
  • Develop secure coding guidelines and provide practical security guidance to engineering teams.
What You'll Need
  • At least 3 years of hands-on experience in penetration testing, application security, DevSecOps, or a similar security role.
  • Strong knowledge of web application and API security.
  • Good understanding of OWASP Top 10, OWASP API Security Top 10, common attack techniques, and secure coding principles.
  • Hands-on experience with tools such as Burp Suite, Nmap, Nuclei, SQLmap, or equivalent tools.
  • Ability to perform manual security testing and vulnerability validation.
  • Understanding of authentication, authorization, HTTP/HTTPS, APIs, TLS, and common web technologies.
  • Experience with CI/CD pipelines and security tools such as SAST, DAST, SCA, secrets scanning, container scanning, or IaC scanning.
  • Familiarity with Docker, Kubernetes, and container security.
  • Working knowledge of at least one scripting or programming language such as Python, Bash, JavaScript, or Go.
  • Ability to clearly communicate security findings and remediation recommendations.
Nice to Have
  • Advanced web, API, or mobile penetration-testing experience.
  • Experience securing Kubernetes-based environments.
  • Experience with GitLab CI/CD, GitHub Actions, Jenkins, Argo CD, or similar platforms.
  • Hands-on experience with tools such as Semgrep, SonarQube, Snyk, Trivy, Gitleaks, OWASP ZAP, or Checkov.
  • Experience with cloud application security in AWS, Azure, or Google Cloud.
  • Experience with bug bounty programs, security research, or CTF competitions.

Job Requirements

Gender
Men / Women

ثبت مشکل و تخلف آگهی

ارسال رزومه برای گروه توسعه همراه تل